AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to register
20automated residualNeeds reviewAbove working threshold (12)

Prompt injection of institutional systems

Owner · Courts, enterprises, and model vendors

AffordanceImpact domainBoth

Statement (NASA form)

Given that untrusted text is concatenated into model context in courts, enterprises, and consumer products, and prompt injection remains the leading unfixed LLM failure, there is a possibility of an adversary steering a model that drafts, ranks, or decides inside an institution resulting in corrupted legal filings, leaked data, and decisions that look official but were written by an attacker.

Condition
untrusted text is concatenated into model context in courts, enterprises, and consumer products, and prompt injection remains the leading unfixed LLM failure
Departure
an adversary steering a model that drafts, ranks, or decides inside an institution
Impact
corrupted legal filings, leaked data, and decisions that look official but were written by an attacker

VC + institute corroboration

Experimental share of compiled public capital that names this risk. Not a certified residual.

$29Mexperimental share · $29M private / $0k institute · partial corroboration

5 public sources · OECD AIM · AIID / ABC · OWASP LLM Top 10 2026

Worst scenario
4×4
Likely × Critical
Urgency
4
Expedite · This month
Inherent composite
20
Worst 16 + urgency
Residual composite
20
Need ≤ 12

A US court has already sanctioned a filing that hid white-on-white prompt-injection aimed at an AI reader. Practitioners still rank the same bug as number one. Any organisation that lets a model read email, PDFs, or the web has imported this risk.

Pathway fragment

Simple upstream → via → downstream notes. Not a causal graph. Experimental.

Upstream
  • Untrusted retrieved text
  • Tool schemas as prompts
  • Institutional agents
Via
  • Hidden instruction executes
  • Filing or transfer issued
Downstream
  • Corrupted legal or enterprise action
  • Data exfiltration

Assumptions · Assumes isolation of untrusted content is still optional in most deployments.

Human calibration

Override is stored on this desk only. It does not make the score official.

Failure scenarios

Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.

A court or agency acts on injected text

3Probable4Critical12

A filing or comment steers a model-assisted clerk toward a wrong ruling or a leaked draft.

Enterprise agent follows hostile instructions in a document

4Likely4Critical16

A PDF, ticket, or email tells the agent to exfiltrate a warehouse or wire funds.

Injection in a widely scraped corpus

3Probable3Major9

Poisoned web pages steer every model that trained or retrieved on them.

Examples

Hidden text in a court filing

A US court sanctioned counsel for a white-on-white prompt intended to steer an AI reader of the brief.

Still the top unfixed failure

Practitioners continue to rank prompt injection as the leading unfixed LLM security problem.

Inbox-to-action agents

An agent that reads mail and then pays invoices, books travel, or changes ACLs is a prompt-injection terminal.

Contributing signals

X posts on the desk that evidence this risk. A signal can contribute to more than one risk.

Court-sanctioned hidden prompt-injection in a filing.

Practitioners still rank injection as the top unfixed failure.

Gray Swan $40M Series A converting into red-team headcount.

Langflow: 12 known-exploited vulns in 2026; 15k+ canary hits. Agent endpoints are the new injection surface.

Mitigations

Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.

ProposedOn the pathEnterprises and courts

Dual control on irreversible actions

Wires, filings, ACL changes, and outbound mail require a second channel.

Enterprises and courts · expedited 2 weeks · normal 2 months · −0 L · −2 C · −0 U

ProposedCourts and ECF vendors

Hidden-text and steganographic scanning of filings

Courts and document platforms strip or flag white-on-white, tiny-font, and metadata payloads.

Courts and ECF vendors · expedited 3 weeks · normal 3 months · −1 L · −0 C · −1 U